Last week I wrote about the cyber attack on Manchester Airports Group (MAG) — the company that runs Manchester, London Stansted and East Midlands airports — and urged everyone who had used those airports to stay alert to scams. I’m following that piece up today, because there has been a serious and worrying development.
The stolen data is now public.
MAG declined to pay the ransom the attackers demanded. For what it’s worth, I believe refusing to pay is the right call, and it is exactly what official guidance advises — paying funds the next attack and never guarantees your data is returned. But the criminals have now carried out their threat: they have published the stolen data online, roughly 550GB of it, and offered it free to any other criminal or scammer who wants to download it. The BBC confirmed the leak at the start of this week.
What this means for you
The information that has been dumped covers around 8.8 million people and includes email addresses, phone numbers, vehicle registrations, postcodes and booking history — car park, lounge and Fast Track bookings, and in-terminal WiFi sign-ups across the three airports.
Here is the crucial difference between last week and this week. When a breach is first disclosed, the stolen data usually sits with one criminal group. Once it is published, it is in the public domain permanently. It cannot be recalled, deleted or put back. Anyone, anywhere, can download it. In plain terms: if your email address and phone number were in that database, they are now public data — sitting on the open internet, for good.
Your email — and maybe your password — may already be public
An exposed email address is bad enough on its own. But this incident points to a much bigger reality that everyone should understand. Breaches like this happen constantly — hundreds of them every year — and it is not only email addresses that leak. Passwords leak too. Criminals collect these dumps, combine them, and run them automatically against websites and email accounts. If you have ever reused the same password across more than one site, a password exposed in any breach becomes a key that can unlock your other accounts. For millions of people, their email address and a working password are already public data without them realising it.
So I want to point you to one free tool that I genuinely believe everyone should use — every business owner, every member of staff, and every member of your family:
Have I Been Pwned (haveibeenpwned.com) lets you enter your email address and instantly see, for free, every known data breach your details have appeared in. It is run by a well-respected security researcher, it is trusted right across the industry, and it never asks you for your password. We seriously recommend this. Do it today — and get your team to do it too.
What to do if you’re affected
- Check Have I Been Pwned for every email address you use, personal and work.
- Change your password on any account tied to an exposed email — and change it anywhere you have reused that same password.
- Use a unique, strong password for every account. A password manager makes this effortless and remembers them all for you.
- Turn on multi-factor authentication (MFA) everywhere you can, so a stolen password on its own is not enough to get in.
- Expect convincing scams. With your email, phone number and airport history now public, be ready for fake “parking refund” or “problem with your booking” messages. MAG will never contact you out of the blue to ask for payment or passwords — so anything that does is a scam.
No organisation is too big to be breached
I made this point last week, and this leak underlines it. MAG is a large, well-resourced organisation with sophisticated systems — and it was still breached. According to security researchers, the attackers got in after finding live access keys sitting in the code of the airports’ own public websites. In other words, it wasn’t exotic wizardry; it was a basic oversight that left the keys to the front door on display.
That is the real lesson for every business, whatever your size. Attackers no longer need to break down the walls if the keys are left on the doorstep. Getting the fundamentals right — knowing where your credentials and data live, enforcing MFA, monitoring your systems and keeping your people alert to phishing — protects you far more than the size of your budget ever will.
How Foresight can help
This is exactly the work we do. Foresight helps organisations across Greater Manchester and the UK build genuine cyber resilience — staff awareness training, multi-factor authentication, 24/7 monitoring, vulnerability scanning and Cyber Essentials certification. We are Cyber Essentials Plus certified ourselves, and we would far rather help you prepare than help you recover.
But the single most important thing you can do this week takes two minutes and costs nothing: go to haveibeenpwned.com, check your email address, and act on what you find. We seriously recommend it.
Sources: BBC, SecurityWeek and Infosecurity Magazine reporting on the Manchester Airports Group data leak, and MAG’s own data security incident statement. This article is for general awareness and reflects public reporting at the time of writing. “Have I Been Pwned” is an independent service operated by Troy Hunt and is not affiliated with Foresight.